Home › Data security and quality assurance

Offshore staff data security: how Australian privacy law applies and how Offshored protects your data

General information for Australian business owners and managers, not legal advice.

Is it safe to share data with offshore staff?

Yes, when three conditions are met. First, your business follows the Privacy Act 1988, including Australian Privacy Principle 8 on overseas disclosure. Second, your provider screens its people and binds them to confidentiality in writing. Third, the work happens inside systems you control, with access you can limit and remove. The rest of this page explains each condition and exactly what Offshored does.

Every Offshored team member is screened by interview and NBI clearance before being put forward, works inside the client's own systems and logins, and signs confidentiality and intellectual property clauses as part of their employment contract with Australian Pathways OPC, and every client login is removed on their last day.

  1. Is it safe to share data with offshore staff?
  2. How the Privacy Act 1988 applies when your team member is in the Philippines
  3. The controls Offshored puts around every team member
  4. What you still need to do as the client
  5. Quality assurance: how work is checked
  6. Philippine law that also applies
  7. Pre-engagement data checklist
  8. Frequently asked questions
Australian law

How the Privacy Act 1988 applies when your team member is in the Philippines

The Privacy Act 1988 covers most Australian businesses with annual turnover above A$3 million, plus some smaller ones such as health service providers. If it covers you, three parts of it matter when you engage offshore staff.

APP 8, cross-border disclosure

Before you disclose personal information to an overseas recipient, APP 8 requires you to take reasonable steps to ensure the recipient does not breach the Australian Privacy Principles. The Office of the Australian Information Commissioner (OAIC) says that giving personal information to an overseas contractor is a disclosure in most circumstances, and that the reasonable step is usually an enforceable contract. Under section 16C of the Act, you remain accountable for what the overseas recipient does with the information.

APP 11, security

You must take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access. Since the 2024 amendments, the Act states that reasonable steps include both technical measures, such as access controls and multi-factor authentication, and organisational measures, such as policies and training. APP 11 also requires you to destroy or de-identify personal information once it is no longer needed.

The Notifiable Data Breaches scheme

If personal information you hold is lost or accessed without authorisation and serious harm is likely, the Notifiable Data Breaches scheme requires you to notify the OAIC and the affected individuals. A suspected breach must be assessed within 30 days. The obligation is the same whether the person involved sits in Sydney or Manila, which is why your incident plan should name your offshore team member and your Offshored account manager.

None of this prohibits offshoring. It sets the standard you have to meet, and our guide Is offshoring legal in Australia? covers the wider legal picture.

Sources: OAIC, APP guidelines chapter 8, cross-border disclosure of personal information; OAIC, APP guidelines chapter 11, security of personal information; OAIC, About the Notifiable Data Breaches scheme.

Our controls

The controls Offshored puts around every team member

These are the controls in place today, stated as they actually operate.

  • Screening. Every candidate has a pre-screening interview with Offshored before being endorsed to you, and every hire provides an NBI clearance, the Philippine national police check.
  • Contract. Every team member is employed in the Philippines by Australian Pathways OPC, a registered Philippine company. The employment contract includes a confidentiality clause, which continues to apply after employment ends, and an intellectual property assignment clause, so work product belongs to you.
  • Your systems, your data. Work is done in your systems, under logins you issue and control. Team members connect through a VPN or directly through your own platforms, depending on your IT setup. Offshored holds no client data on its own infrastructure.
  • Devices. Office based staff in our BGC, Manila office work on company supplied laptops. Most team members work from home and usually use their own hardware, and Offshored supplies laptops to home based staff where required. USB ports and personal cloud drives are blocked on company supplied devices. If your data calls for that level of control, you can require a company supplied device for your team member.
  • Work location. Team members work from home, from our BGC office or a mix of the two. Office based placements are arranged by agreement with you.
  • Exit. All client system logins are removed on the team member's last day.
  • Consequences. Under our Terms of Service, unauthorised access, disclosure, copying, loss or misuse of client data is a serious breach that can mean immediate termination, civil liability and criminal prosecution. You may also require a separate non-disclosure agreement.

Offshored is not ISO 27001 certified today, and we do not claim any certification we do not hold.

Your side

What you still need to do as the client

Because the work happens in your systems, part of the protection is in your hands. Four steps cover most of it.

  • Grant least-privilege access. Give each team member only the systems and permission levels the role needs, and review them when the role changes.
  • Turn on multi-factor authentication. Use it on every system your team member touches, along with individual logins, never shared ones.
  • Update your privacy policy. State that personal information may be disclosed to recipients overseas, and name the Philippines. You can see how we word it in our own privacy policy.
  • Add an offboarding step. Put your offshore team member in the same exit checklist as local staff, so you can confirm on the last day that every login is closed.
Quality assurance

Quality assurance: how work is checked

You direct the daily work, and Offshored manages the employment relationship around it, as set out in How it works.

  • Clear measures from the start. KPIs for the role are agreed with you at onboarding, and later reviews are held against them.
  • Reviews in the first six months. Every hire serves a six month probation. We formally ask for your feedback at the end of month one, month three and month six, and review performance with you at each point.
  • Account manager check-ins. Every client has a named account manager who checks in with you and with your team member, and steps in early when something is off track.
  • Attendance and responsiveness. Every shift is logged on our timekeeping platform, attendance records are available on request, and team members are expected to answer messages within ten minutes during work hours.
  • Annual review. Performance is reviewed each year alongside the annual salary review.
  • Replacement. If a team member resigns or is not the right fit, Offshored recruits a replacement at our cost. Engagements run with 30 days' notice and no lock-in contract.
Philippine law

Philippine law that also applies

The Data Privacy Act of 2012 (Republic Act 10173) is the privacy law of the Philippines, enforced by the National Privacy Commission. It requires organisations to keep reasonable organisational, physical and technical security measures, and it sets prison terms and fines for unauthorised processing, access and disclosure of personal information. The Act contains a carve-out for personal information that was collected from residents of another country under that country's laws and is being processed in the Philippines. For your customers' data, that means the Australian Privacy Act remains the governing standard. Treat Philippine law as a second layer of protection, not a substitute for APP 8.

Source: National Privacy Commission, Republic Act 10173, Data Privacy Act of 2012.

Checklist

Pre-engagement data checklist

Copy these eight items into your onboarding plan before your team member's first day.

  1. List the systems the role needs and the permission level for each.
  2. Create an individual login for every system. No shared passwords.
  3. Turn on multi-factor authentication for each login.
  4. Decide whether the role requires a company supplied device, and tell Offshored before recruitment starts.
  5. Confirm how the team member will connect: VPN or direct access to your cloud platforms.
  6. Add the overseas disclosure line, naming the Philippines, to your privacy policy.
  7. Decide whether you want a separate non-disclosure agreement in addition to the employment contract clauses.
  8. Add your team member and your Offshored account manager to your data breach response plan and your offboarding checklist.
FAQ

Frequently asked questions

Can offshore staff access my bank?

Only if you give them access. You control every login. A common setup is to give finance staff access to the accounting software and a bank feed or a view-only profile, and to keep payment approval with an Australian signatory. Where a team member prepares payment batches, a two person approval keeps the final release with you.

Where is my data stored?

In your own systems. Offshored team members work inside your platforms under logins you control, and Offshored holds no client data on its own infrastructure. Where your data physically sits depends on the software providers you already use.

What happens after someone leaves?

All client system logins are removed on the team member's last day, and Offshored recruits a replacement at our cost. The confidentiality clause in the employment contract with Australian Pathways OPC continues to bind the team member after their employment ends. Add the departure to your own offboarding checklist so you can confirm that each login is closed.

Are staff background checked?

Yes. Every candidate has a pre-screening interview with Offshored before being endorsed to you, and every hire provides an NBI clearance, the national police check issued by the Philippines' National Bureau of Investigation.

Is Offshored ISO 27001 certified?

Not today. The controls on this page are the ones in place now, and we would rather describe them precisely than point to a certificate we do not hold.

More questions? The full FAQ covers the legal employer, time zones, replacement and the minimum commitment, and the glossary defines APP 8, the Notifiable Data Breaches scheme and the Data Privacy Act.

This page is general information only, not legal advice. Laws and OAIC guidance change. Check the primary sources linked above and obtain advice specific to your business.

Talk to us about your data requirements.

Ask for our data handling summary and we will send a short document you can give your IT provider or your board. Or book a 20-minute call and walk us through your systems. We reply within one business hour, 8am to 6pm AEST, Monday to Friday.

Ask for our data handling summary Book a 20-minute call